Fraudulent Ads Generate 304 Million Impressions Across Europe in Under One Month

Scam advertisements generated more than 304 million impressions across the European Union and United Kingdom in under one month, showing how advertising platforms continue to give fraud operators massive reach.

The findings come from Gen’s Scam Ad Machine research, which analyzed millions of advertisements delivered to European audiences.

Gen analyzed 14.57 million advertisements, representing 10.76 billion impressions, across the EU and the UK during 23 days. Researchers identified 4.51 million scam-related advertisements nearly one in three ads in the analyzed dataset.

Those ads generated 143.8 million impressions in the EU and 304.11 million impressions across the EU and UK

The volume highlights a growing malvertising problem in which attackers use paid advertising to direct users to fraudulent stores, phishing pages, investment scams, fake software downloads, and tech-support fraud.

Unlike traditional phishing emails, scam ads are delivered through familiar platforms and can appear alongside legitimate content, making them harder for users to recognize as malicious.

Family impersonation SMS (Source: gendigital)
Family impersonation SMS (Source: gendigital)

Fraudulent Ads Hit 304M

Gen said scam operators use a flexible, short-lived advertising model designed to survive moderation and takedown efforts.

Threat actors rely on disposable advertiser accounts, deceptive creatives, multi-facet ads, and rapidly changing campaign infrastructure to keep fraudulent ads active long enough to reach victims.

A malicious ad does not need to remain online for weeks or months to be effective.

It only needs to pass platform checks briefly, reach a targeted audience, and redirect users to a scam page before the advertiser account, domain, or creative is removed. This approach allows attackers to replace blocked campaigns with new ones.

The research aligns with broader scam activity seen in the first half of 2026. Gen reported that scams accounted for nearly 46% of threat detections, while malvertising accounted for almost 30%.

Government impersonation lure from the H1 2026 campaign set. The page borrows official-looking IRS framing and moves the user toward downloading and running an app (Source: gendigital)
Government impersonation lure from the H1 2026 campaign set. The page borrows official-looking IRS framing and moves the user toward downloading and running an app (Source: gendigital)

The company said attackers increasingly abuse trusted digital environments including advertising platforms, cloud hosting services, booking sites, payment workflows, and social-media channels to make fraud appear legitimate.

Fake e-shop campaigns were among the most visible examples. Gen blocked 114.2 million e-shop scam attacks during the first half of 2026, a 109% increase compared with the second half of 2025.

Western European countries, including the UK, Germany, France, Italy, and Spain, accounted for 30.9 million blocked attacks combined, gendigital said.

One campaign used newly registered .click domains promoted through online ads to lure users to convincing-looking shopping websites.

Victims could encounter an ad for a product, land on a disposable storefront, and then be pushed toward a fake checkout process designed to steal payment information or collect personal data.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories